Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > VPN tunnel drops fragments

Reply
Thread Tools

VPN tunnel drops fragments

 
 
profile0104
Guest
Posts: n/a
 
      11-20-2006
Hello

I'm experiencing a strange problem with a GRE over IPSec tunnel between
two Cisco routers.

The configuration is tested and has been working for a long time,
except for a single application. This client-server application works
on UDP and this is what happens:

1) app-client generates a 1800 bytes UDP packet
2) packet is fragmented 1500 + 300 by the first router met
3) the two fragmented packets (1500 and 300) hit the VPN tunnel
interface but they don't make it to the other side of the tunnel. It
looks as they're silently dropped, app-server never sees them.

The tunnel works in transport mode and ip mtu is set to 1440 bytes, the
load on the VPN routers is very very low. The tunnel perfectly
fragments packets bigger than 1440 but smaller than 1500

Thank you for any advice

 
Reply With Quote
 
 
 
 
Martin Bilgrav
Guest
Posts: n/a
 
      11-20-2006
Not sure but maybe this :

http://www.cisco.com/en/US/products/...html#wp1029667


"profile0104" <> wrote in message
news: oups.com...
> Hello
>
> I'm experiencing a strange problem with a GRE over IPSec tunnel between
> two Cisco routers.
>
> The configuration is tested and has been working for a long time,
> except for a single application. This client-server application works
> on UDP and this is what happens:
>
> 1) app-client generates a 1800 bytes UDP packet
> 2) packet is fragmented 1500 + 300 by the first router met
> 3) the two fragmented packets (1500 and 300) hit the VPN tunnel
> interface but they don't make it to the other side of the tunnel. It
> looks as they're silently dropped, app-server never sees them.
>
> The tunnel works in transport mode and ip mtu is set to 1440 bytes, the
> load on the VPN routers is very very low. The tunnel perfectly
> fragments packets bigger than 1440 but smaller than 1500
>
> Thank you for any advice
>



 
Reply With Quote
 
 
 
 
profile0104
Guest
Posts: n/a
 
      11-22-2006
Thank you Martin, but my routers are two 2691 and I don't think there's
a similar command for them

Martin Bilgrav wrote:
> Not sure but maybe this :
>
> http://www.cisco.com/en/US/products/...html#wp1029667
>
>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASA: L2L VPN tunnel Drops Every 24 hours ankitm Cisco 0 04-26-2009 09:07 PM
Site to site VPn tunnel and VPN tunnel Trouble Cisco 1 08-04-2006 08:09 AM
Site to site VPn tunnel and VPN tunnel Trouble Cisco 0 08-04-2006 04:23 AM
Split Tunnel Blocks http through tunnel but passes http around tunnel a.nonny mouse Cisco 2 09-19-2004 12:10 AM
Termination of an IPSec VPN tunnel and a GRE Tunnel on one physical interface. John Ireland Cisco 1 11-11-2003 04:47 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57